funktioniert dein Setup jeweils mit DynDNS auf der dezentralen Seite?
Nutzt du die alte oder neue GUI. Wenn du DynDNS zum Laufen bekommen hast (egal mit alt oder neu), dann gerne deine Config mal teilen
vpncfg { connections { enabled = yes; conn_type = conntype_lan; name = "<User defined name in Fritzbox>"; always_renew = no; reject_not_encrypted = no; dont_filter_netbios = yes; localip = 0.0.0.0; local_virtualip = 0.0.0.0; remoteip = 0.0.0.0; remote_virtualip = 0.0.0.0; localid { fqdn = "<local id>"; } remoteid { fqdn = "<remote id>"; } mode = phase1_mode_aggressive; phase1ss = "dh15/aes/sha"; keytype = connkeytype_pre_shared; key = "***************************************************************"; cert_do_server_auth = no; use_nat_t = no; use_xauth = no; use_cfgmode = no; phase2localid { ipnet { //Fritzbox ipaddr = 192.168.1.0; mask = 255.255.255.0; } } phase2remoteid { ipnet { //OpnSense ipaddr = 10.0.0.0; mask = 255.0.0.0; } } phase2ss = "esp-aes256-3des-sha/ah-no/comp-lzs-no/pfs"; accesslist = "permit ip 192.168.1.0 255.255.255.0 10.0.0.0 255.0.0.0"; } ike_forward_rules = "udp 0.0.0.0:500 0.0.0.0:500", "udp 0.0.0.0:4500 0.0.0.0:4500";}// EOF
=============================IPsec -> connection [new]=============================General settings: - Enabled: yes - Proposals: aes256-sha512-modp3072 - Unique: Replace - Aggressive: enabled - Version: IKEv1 - Mobike: disabled - Local adresses: <DynDNS of Opnsense> - Remote adresses: <DynDNS of Fritzbox> - UDP encapsulation: disabled - Re-auth time (s): 3600 - Rekey time (s): <empty> - Over time (s): <empty> - DPD delay (s): <empty> - DPD timeout (s): <empty> - Pools: Nothing selected - Send cert req. disabled - Send certificate: never - Keyingtries: 5 - Description: <User defined name in Opnsense>Local authentication: - Enabled: yes - Connection: <Name mentioned in general settings> - Round: 0 - Authentication: Pre-Shared Key - Id: <Remote id mentioned in Fritzbox VPN config> - Certificates: Nothing selected - Description: <User defined description>Remote authentication: - Enabled: yes - Connection: <Name mentioned in general settings> - Round: 0 - Authentication: Pre-Shared Key - Id: <Local id mentioned in Fritzbox VPN config> - Certificates: Nothing selected - Description: <User defined description>Children: - Enabled: yes - Connection: <Name mentioned in general settings> - Mode: Tunnel - Policies: enabled - Start action: Trap - DPD action: Trap - ReqId: <empty> - ESP proposals: aes256-sha512-modp3072, aes256gcm16-sha256-modp3072 - Local: 10.0.0.0/8 - Remote: 192.168.1.0/24 - Description: <User defined description>=============================IPsec -> Preshared Keys============================= - Local identifier: <Id mentioned in General settings -> Local authentication> - Remote identifier: <Id mentioned in General settings -> Remote authentication> - Pre-Shared Key: <Same key as in Fritzbox VPN config> - Type: PSK
Frage: Hast du schon eine Fritz mit IKEv2 laufen?